DongHa Lee
40 posts

DongHa Lee
@gap_dev
Vulnerability Researcher in KR 👋 / / [email protected]
Seoul, Republic of Korea शामिल हुए Temmuz 2025
114 फ़ॉलोइंग412 फ़ॉलोवर्स

I have posted a write-up for those who are interested in building virtual iPhone.
If have any further questions, please feel free to reach out via DM, Thanks.
github.com/wh1te4ever/sup…
English
DongHa Lee रीट्वीट किया

Some demo about running Virtual iPhone using Apple Virtualization framework:
youtu.be/3vvrU0YGKCQ

YouTube

English

@MrKaLi176442 Varies case by case.
Probably tied to the quarter cycle, so from my experience it can take up to ~6 months.
I don’t know exactly though.😭
English

@MrKaLi176442 I reported this bug in June, received a CVE in October, and the bounty has now been addressed.
English

DongHa Lee रीट्वीट किया

🤌🔥 "Build a Fake Phone, Find Real Bugs
Qualcomm GPU Emulation and Fuzzing with LibAFL QEMU"
media.ccc.de/v/39c3-build-a…
English
DongHa Lee रीट्वीट किया

On Apple Silicon, the GPU by default cannot use more than about 75% of the system's total memory, but you can change this setting easily. I use my own script for that and set it up to 98% on M3 Ultra 512GB.
gist.github.com/ivanfioravanti…
English

I’m not affiliated with Talos.
I’m an independent security researcher, so I don’t really know the details of the other bug.
For my bug, I found it quite a while ago, and it looks like the credit process got missed after I reported it (it’s being sorted out now lol).
As for exploitation: at least when I analyzed it back then, I didn’t see a viable way to get a shell. Even though it’s a stack overflow, I couldn’t find a memory layout that I could realistically overwrite in a useful way.

English

@gap_dev does the new binary also ship withouth pie ? since stack overflow u could technically redirect to the vuln section where u put ropchain there right to get shell ?
English

@f00fc7c800 Yep, it’s a stack overflow, but no shell😅
Not entirely sure where the line is drawn for calling this code execution
English

@gap_dev yo is it really a stack overflow ? that s nice did u manage to leverage it to shell ? i worked on something else on cuobjdump and didnt manage to get shell :/
English

@gap_dev 만약 Hypervisor가 있다고 해도 Entitlements가 있어야 해서 17.0.1 이상에서는 불가능하고요. developer.apple.com/documentation/…
한국어














